PkgRadar

npm Ā· registry.npmjs.org

@bluevs/ttcli

Install Lifecycle Remote Or Exec: postinstall="node -e \"console.log('\\nšŸ“¦ ttcli installed. To install the openclaw skill, run:\\n bash $(npm root -g)/@bluevs/ttcli/skills/ttcli/scripts/install-skill.sh\\n')\""

Why PkgRadar flagged 0.0.8

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"console.log('\\nšŸ“¦ ttcli installed. To install the openclaw skill, run:\\n bash $(npm root -g)/@bluevs/ttcli/skills/ttcli/scripts/install-skill.sh\\n')\"" Ā· package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.8High risk352026-06-10
0.0.7High risk352026-06-10
0.0.6High risk352026-06-10
0.0.5High risk352026-06-10
0.0.4High risk352026-06-10
0.0.3High risk352026-06-10
0.0.2High risk752026-06-10
0.0.13Review52026-06-08
0.0.12Review52026-06-05
0.0.11Review52026-06-05
0.0.9Review52026-06-05
0.0.10Review52026-06-05
0.0.1Low risk02026-06-02

Campaign attribution

Part of the Clob dropper campaign.

Block this in CI

PkgRadar gates @bluevs/ttcli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @bluevs/[email protected]